Skip to content

JWT Verify — Reference

Reference · Advanced · Server Connect

Verify a token before considering its claims for application decisions.

Verify a token before considering its claims for application decisions.

  • A Server Connect action. Test security behavior with an isolated test account or test-only token/key, not production credentials.

Verify a token before considering its claims for application decisions.

Setting Meaning and example
NameNames the verification result. A successful result is the payload, not the full decoded header/signature envelope.
TokenThe JWT string to verify. Do not substitute a previously decoded object.
KeyThe verification key: the matching shared secret for HS tokens or public key for RS tokens. Use a key and accepted algorithm from trusted configuration, not values chosen by the incoming token.
Throw ErrorIn Node.js, on failure this either throws or returns an object containing error; the default is false. In the installed PHP module, verification exceptions are caught and the result is null; this flag is not applied in the same way.

Verify a known test token, then repeat with the wrong key and a modified payload. Node.js should return payload on success and either throw or return {error:…} on failure. PHP returns null for a caught verification failure. In particular, a truthy Node.js result object is not sufficient evidence of success.

The inspector exposes Token, Key and Throw Error, not a complete token-acceptance policy. Enforce issuer, audience, time and allowed-algorithm requirements from trusted configuration. The installed PHP helper checks signature and expiration but does not implement equivalent audience/issuer/not-before checks. Do not treat this step alone as a complete authorization policy.

Use the security and login guides for the surrounding provider, form, session and server-access configuration.

You can configure the documented fields and distinguish a successful result from the failure or limitation described here.